I need a solution
My customer in Russia uses SEP 12.1.2 with latest updates. He reported that one of his systems (accounting server) was infected and users' and database files was encrypted. The files are renamed, the template is %ID%help@antivirusebola.com
One of our competitor's web site determines the threat as Cryptor.701. The encryption algorithm is AES with 128 bit key. Can we decrypt these files? Can we protect the systems from this threat? What can we do to help Symantec protect customers from this?